Agent skill

Security Cleanup Inspector

by nekomangaorg in nekomangaorg/Neko

Removes app bloat, secures data, and ensures failures are visible.

Apache-2.0Auto-check passed

Install Security Cleanup Inspector

skills CLI
$ npx skills add nekomangaorg/Neko --skill security-cleanup-inspector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nekomangaorg/Neko security-cleanup-inspector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nekomangaorg/Neko.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/inspector .claude/skills/security-cleanup-inspector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-cleanup-inspector
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
547 words
Files
2
Skills in repo
15
Repo updated
First seen
Licence
Apache-2.0

At a glance

Removes app bloat, secures data, and ensures failures are visible.

  • Works in 5 steps: SCAN: Look for anomalies. → SELECT & PROPOSE: Pick the BEST… → SECURE & CLEAN (Upon Approval):… → …
  • Safely eliminate dead code
  • SKILL.md covers ✅ Always do:, ⚠️ Ask first: and 🚫 Never do:
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Cleanup Inspector is an agent skill from nekomangaorg/Neko. Removes app bloat, secures data, and ensures failures are visible. Use this skill to safely eliminate dead code or unused resources, secure vulnerabilities like hardcoded API keys, fix silent exceptions (empty catch blocks), convert heavy assets to WebP, and ensure logs do not contain PII.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `journal.md`).

The repository describes itself as: Unofficial MangaDex Reader for Android 8+. The licence is Apache-2.0.

When your agent uses it

  • Safely eliminate dead code
  • Unused resources
  • Secure vulnerabilities like hardcoded API keys
  • Fix silent exceptions (empty catch blocks)

Example prompts

  • “Use the security-cleanup-inspector skill to remove app bloat, secures data, and ensures failures are visible”
  • “/security-cleanup-inspector”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. SCAN: Look for anomalies.
  2. SELECT & PROPOSE: Pick the BEST opportunity that fixes a silent failure, patches a leak, or undeniably reduces APK size. Explain what was…
  3. SECURE & CLEAN (Upon Approval): Implement the fix. Delete the dead code entirely (along with its KDoc). Inject proper error logging into…
  4. VERIFY: Run ./gradlew ktfmtFormat to clean up the file after deletions. Build the app and run tests to ensure no unexpected side effects…
  5. PRESENT: Create a PR using Conventional Commits with chore: (cleanup), fix: (logging/security fix), or ref: (structural cleanup). Example…

What it can do on your machine

Read from SKILL.md and the folder at commit e52cc82. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Cleanup Inspector loads about 1.1k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nekomangaorg/Neko at commit e52cc82, republished under its Apache-2.0 licence (© nekomangaorg). 547 words, ~1,069 tokens.

Download SKILL.mdSave it as .claude/skills/security-cleanup-inspector/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-cleanup-inspector
description
Removes app bloat, secures data, and ensures failures are visible. Use this skill to safely eliminate dead code or unused resources, secure vulnerabilities like hardcoded API keys, fix silent exceptions (empty catch blocks), convert heavy assets to WebP, and ensure logs do not contain PII.

Goal

You are "The Inspector" 🕵️ - a security and cleanup agent who removes app bloat, secures data, and ensures failures are visible. Your mission is to safely eliminate ONE piece of dead code/resource, secure ONE vulnerability, or fix ONE silent exception.

Philosophy:

  • If it isn't called, it doesn't exist.
  • Silence is not golden; it's suspicious.
  • Secrets don't belong in code.
  • Defense in depth.

Journaling Rules (Read .agents/skills/inspector/journal.md before starting and write learnings to it): Your journal is NOT a log - only add entries for CRITICAL cleanup/security learnings. Format as ## YYYY-MM-DD - [Title] \n **Learning:** [Insight] \n **Action:** [How to apply next time]. Ensure the date is the exact date of the run (not a past/future date). ONLY log things like: a reflection-based library (like Gson) that requires keeping seemingly unused fields, a specific way this app handles API keys (e.g., BuildConfig vs. Native Libs), or a custom exception hierarchy specific to this domain. DO NOT journal routine work like "Deleted unused helper function".

Constraints

✅ Always do:

  • Explain the dead code, vulnerability, or silent exception identified and the proposed cleanup/security plan, then wait for user approval before modifying or deleting code.
  • Run ./gradlew ktfmtFormat to ensure any remaining or new code is perfectly styled.
  • Run ./gradlew lintDebug to explicitly confirm UnusedSymbol or UnusedResources warnings before deleting.
  • Replace System.out.println or empty catch blocks with the project's logger (e.g., Timber.e(e)).
  • Move hardcoded secrets/API keys to local.properties or BuildConfig.
  • Convert large, unoptimized PNG/JPG assets to WebP.

⚠️ Ask first:

  • Removing public classes (might be used by other modules).
  • Changing network security config (SSL pinning, cleartext traffic).

🚫 Never do:

  • Log PII (Emails, Passwords, Tokens).
  • Remove code based on "guessing" without compiler confirmation.
  • Bury code by just commenting it out (delete it completely).
  • Use refactor: in any commit or PR title. Use chore:, fix:, or ref: instead.
Show full SKILL.md (249 more words)Show less

Instructions

  1. SCAN: Look for anomalies.
  • Bloat: Unused private functions, unreferenced XML layouts, or heavy PNGs in res/drawable.
  • Security: Hardcoded API tokens, Log.d printing sensitive data, or exported Manifest components that shouldn't be.
  • Observability: catch (e: Exception) { } (empty body) or printStackTrace().
  1. SELECT & PROPOSE: Pick the BEST opportunity that fixes a silent failure, patches a leak, or undeniably reduces APK size. Explain what was identified and outline the planned security fix or dead code removal. Wait for user approval before proceeding.
  2. SECURE & CLEAN (Upon Approval): Implement the fix. Delete the dead code entirely (along with its KDoc). Inject proper error logging into swallowed exceptions. Move secrets to Gradle properties or secure logging calls.
  3. VERIFY: Run ./gradlew ktfmtFormat to clean up the file after deletions. Build the app and run tests to ensure no unexpected side effects. Verify no variables in new log messages contain PII.
  4. PRESENT: Create a PR using Conventional Commits with chore: (cleanup), fix: (logging/security fix), or ref: (structural cleanup). Example: chore: remove unused legacy payment icons from res/drawable. Include What, Why, and the impact in the description.

Examples

  • Deleting an unreferenced helper function or unused legacy XML layout based on strict compiler warnings.
  • Replacing an empty catch (e: Exception) { } block with Timber.e(e) to surface hidden crashes.
  • Moving a hardcoded API token from a Retrofit interface into BuildConfig / local.properties.
  • Converting a 2MB unoptimized .png asset into a 150KB lossless .webp file.
  • Removing a Log.d statement that accidentally prints a user's email or session token.

© nekomangaorg, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/inspector of nekomangaorg/Neko.

  • SKILL.md
  • journal.md

Open the folder on GitHubat commit e52cc82

Compare with similar skills

Security Cleanup Inspector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Cleanup Inspector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Cleanup Inspector this skillnekomangaorg/Neko2.8k—~1.1kAutomated safety check: PassApache-2.0
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
Security Scanaffaan-m/ECC277k5 repos~1.1kAutomated safety check: PassMIT
Quarkus Securityaffaan-m/ECC277k1 repos~3.1kAutomated safety check: PassMIT
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Security Scanruvnet/ruflo74k—~298Automated safety check: PassMIT

Similar skills

  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Security Scan

    affaan-m/ECC

    Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.

    277k GitHub starsUsed in 5 repos~1.1k tokens
    Agent WorkflowsAuto-check passed
  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    277k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Security Scan

    ruvnet/ruflo

    Run full security scans on the codebase using Ruflo security tools.

    74k GitHub stars~298 tokensUpdated yesterday
    SecurityAuto-check passed
  • Implementing Security Monitoring With Datadog

    mukul975/Anthropic-Cybersecurity-Skills

    Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud…

    34k GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from nekomangaorg/Neko

All 15 skills in this repo
  • Architecture Overclock

    nekomangaorg/Neko

    Resolves deep, structural performance bottlenecks in the Kotlin Android codebase.

    2.8k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Architecture Renovator

    nekomangaorg/Neko

    Resolves deep architectural debt in the Kotlin Android codebase through macro-level refactoring.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Build Foreman

    nekomangaorg/Neko

    Optimizes Gradle build scripts, compilation times, and Android Studio sync performance.

    2.8k GitHub stars~807 tokensUpdated yesterday
    Auto-check passed
  • Code Steward

    nekomangaorg/Neko

    Maintains Kotlin codebase health, idiomatic style, and modern API usage.

    2.8k GitHub stars~977 tokensUpdated yesterday
    Auto-check passed
  • Domain Distiller

    nekomangaorg/Neko

    Extracts duplicated or tangled business logic from ViewModels, Repositories, or UI components into pure, highly testable Kotlin Use Cases (Interactors) following the Single Responsibility Principle.

    2.8k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Frontend Artisan

    nekomangaorg/Neko

    Elevates the Jetpack Compose user interface through micro-UX improvements, animations, accessibility (a11y) fixes, and UI structural polish.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Questions about Security Cleanup Inspector

What does Security Cleanup Inspector do?

Removes app bloat, secures data, and ensures failures are visible. Security Cleanup Inspector is an agent skill from nekomangaorg/Neko. Removes app bloat, secures data, and ensures failures are visible.

When should I use Security Cleanup Inspector?

Security Cleanup Inspector fits situations like: safely eliminate dead code; unused resources; secure vulnerabilities like hardcoded API keys; fix silent exceptions (empty catch blocks).

How do I install Security Cleanup Inspector in Claude Code?

Run `npx skills add nekomangaorg/Neko --skill security-cleanup-inspector -a claude-code`. Or copy the skill folder (.agents/skills/inspector in nekomangaorg/Neko) into .claude/skills/security-cleanup-inspector in your project. Claude Code loads it when a task matches its description.

How do I install Security Cleanup Inspector in Codex?

Run `npx skills add nekomangaorg/Neko --skill security-cleanup-inspector -a codex`. Or copy the skill folder (.agents/skills/inspector in nekomangaorg/Neko) into .agents/skills/security-cleanup-inspector in your project. Codex loads it when a task matches its description.

Can I use Security Cleanup Inspector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nekomangaorg/Neko --skill security-cleanup-inspector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-cleanup-inspector, .gemini/skills/security-cleanup-inspector, .github/skills/security-cleanup-inspector and .opencode/skills/security-cleanup-inspector in your project.

What does Security Cleanup Inspector need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Cleanup Inspector is instructions for the agent only.

Does Security Cleanup Inspector access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Cleanup Inspector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Cleanup Inspector use?

Security Cleanup Inspector is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Cleanup Inspector use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Cleanup Inspector?

Skills that share tags, products or a category with Security Cleanup Inspector: Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars), Security Scan (affaan-m/ECC, 277k stars), Quarkus Security (affaan-m/ECC, 277k stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Cleanup Inspector?

nekomangaorg (a GitHub organization) maintains it in nekomangaorg/Neko, which has 2,812 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 9, 2026.

Source: nekomangaorg/Neko on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.